Cyber Resilience Act (CRA) for Embedded Systems Training | Ac6 Training

ac6-training, un département d'Ac6 SAS
EN
EnglishFrench
go-up

ac6 ac6-training Programming Safety and security Cyber Resilience Act (CRA) for Embedded Systems
SEC10Cyber Resilience Act (CRA) for Embedded Systems

Objectives

  • Understand the scope and purpose of the EU Cyber Resilience Act and how it applies to your embedded products
  • Master the essential cybersecurity requirements for secure design and development
  • Learn to conduct compliance gap assessments and create a compliance roadmap
  • Identify compliance pathways, including CE marking and conformity assessment procedures
  • Plan manufacturer obligations from development through end-of-support
  • Evaluate and implement market-ready security solutions for compliance
  • Embedded Systems Engineers building products with digital elements
  • Firmware Architects designing systems for compliance
  • Product Managers overseeing compliance and communicating
  • Manufacturing & Supply Chain teams responsible for product security at all stages
  • Basic Knowledge of Embedded Systems
  • LIVE ONLINE
    • Interactive virtual classroom with remote lab access, digital materials, same expertise as classroom format, available for distributed teams
  • ON-SITE/PRIVATE (Your Facility)
    • Customized to your products, your schedule, your team. Can be tailored to your specific industry or product type.
  • Theoretical course
    • PDF material in English (printed for face-to-face); online over Teams.
    • Trainer assistance throughout.
  • Each session starts with a trainee check-in.
  • Prerequisites are checked before the training.
  • Progress is assessed by quizzes at the end of sections.
  • Each trainee receives a completion certificate.
  • If a prerequisite gap appears, alternative or additional training is offered.

Course Outline

  • Why CRA Matters Now
  • CRA Scope & Applicability - Product classification
  • CRA vs. Related EU Regulations
  • CRA Timeline & Entry Into Force
  • Secure Design & Development
    • Threat modeling
    • Design principles
  • Vulnerability Management
    • Lifecycle approach (discover -> assess -> remediate -> deploy)
  • Transparency & User Information
    • Required disclosures
    • Communication channels
  • Handling Substantial Modifications
    • Decision matrix approach
  • CRA Classification: Important vs. Critical
  • CE Marking & Conformity Assessment
    • self-cert vs. notified body
    • Technical Docs.
  • Case study: Applying conformity assessments to embedded systems
    • Industrial IoT gateway example
    • Step-by-step walkthrough
  • Assessment Pathway Selection Activity
  • Manufacturer Obligations
    • Pre-market, post-market, end-of-life phases
    • Support period expectations
    • clear responsibility mapping
  • Supply Chain Security
    • Due diligence requirements
    • Open source considerations
    • Risk assessment matrix
  • Risk assessment & Due diligence
    • 6-step framework
    • CVSS scoring explained
  • Security Solutions
    • Secure boot architecture
    • Hardware security options (TPMs, Secure Elements)
  • RTOS & OS Security Features
    • Comparison table (Zephyr, Linux, FreeRTOS)
    • CRA readiness scores
  • Compliance Tools and Frameworks
    • Vulnerability scanning tools (e.g., CVE checkers)
    • Compliance management platforms
    • Security testing frameworks
More

To book a training session or for more information, please contact us on info@ac6-training.com.

Registrations are accepted till one week before the start date for scheduled classes. For late registrations, please consult us.

You can also fill and send us the registration form

This course can be provided either remotely, in our Paris training center or worldwide on your premises.

Scheduled classes are confirmed as soon as there is two confirmed bookings. Bookings are accepted until 1 week before the course start.

Last update of course schedule: 27 June 2026

Booking one of our trainings is subject to our General Terms of Sales